Webpack-dev-server: Vulnerability in child dependency for yargs

Created on 20 Mar 2020  路  4Comments  路  Source: webpack/webpack-dev-server

  • Operating System: Windows 10, Linux, macOS
  • Node Version: 12.16.1
  • NPM Version: 6.13.4
  • webpack-dev-server Version: 3.9.0
  • Browser: all

  • [X] This is a bug

  • [ ] This is a modification request

Expected Behavior

webpack-dev-server uses [email protected] that has a child dependency (yarg-parser) that contains a known vulnerability. The vulnerability has been patched in and updated in yargs@>13.0.0.0.

For Bugs; How can we reproduce the behavior?

The reproduction steps are available on the vulnerability disclosure.

https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381

Most helpful comment

@evilebottnawi Where was this updated? The latest yargs in the master branch is still 12.0.5:

https://github.com/webpack/webpack-dev-server/blob/0e9bffbc9617dcc702aad72df77feaa5d1ff58ad/package.json#L71

I also checked the next branch but that seems like it's unused...

All 4 comments

Fixed in deps

@evilebottnawi Where was this updated? The latest yargs in the master branch is still 12.0.5:

https://github.com/webpack/webpack-dev-server/blob/0e9bffbc9617dcc702aad72df77feaa5d1ff58ad/package.json#L71

I also checked the next branch but that seems like it's unused...

There is a try to fix this vulnerability here #2249
However there is some blur on it really exist or not.

This needs to be opened back up. This has not been resolved: https://nvd.nist.gov/vuln/detail/CVE-2020-7608

Was this page helpful?
0 / 5 - 0 ratings

Related issues

hnqlvs picture hnqlvs  路  3Comments

nikirossi picture nikirossi  路  3Comments

wojtekmaj picture wojtekmaj  路  3Comments

adiachenko picture adiachenko  路  3Comments

Jack-Works picture Jack-Works  路  3Comments